ISO/IEC 27001:2022 Annex A · Control 7.9
Security of Assets Off-Premises: A Practical Implementation Guide
Protect organizational assets whenever they leave controlled premises.
This control concerns protecting off-premises assets while traveling, at home, with third parties or in temporary locations.
What should the control achieve?
- Off-premises use is authorized according to risk.
- Custody and location are traceable where necessary.
- Devices and information receive suitable technical and physical safeguards.
- Loss, damage and border or travel risks are managed.
Step-by-step implementation
Define off-premises scenarios
Cover remote work, travel, customer sites, repair, storage and courier transport.
Set authorization and custody
Record asset holder, purpose, location, duration and responsibilities.
Apply protection baseline
Use encryption, screen lock, minimal local data, secure cases and remote disablement.
Provide travel rules
Address vehicles, hotels, airports, borders, high-risk countries and public discussion.
Control third-party handling
Use approved repairers, couriers, contracts and chain of custody.
Respond and reconcile
Report loss promptly, revoke access and confirm return or disposition.
What this could look like in practice
Consultants traveling internationally use managed encrypted laptops with minimal local data. Devices remain carry-on, are not left in vehicles and high-risk destinations require a loan device that is wiped after return.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Home work | Asset is stored securely and household access is prevented. | User acknowledgement |
| Travel | Risk tier determines device and connectivity safeguards. | Travel approval |
| Repair | Approved provider receives device under tracked custody. | Repair record |
| Loss | Sessions are revoked and remote wipe considered. | Incident ticket |
Implementation evidence
- Off-premises policy
- Asset assignments
- Travel risk assessments
- Device baseline
- Courier or repair records
- Loss reports
- Remote actions
- Return reconciliation
Useful metrics
- Off-premises losses
- Lost assets reported within target
- Travel exceptions
- Assets not reconciled
Common mistakes
- Leaving devices in vehicles.
- Assuming encryption addresses physical loss completely.
- Using unknown repair shops.
- Crossing borders without assessing inspection risk.
- Keeping sensitive local copies unnecessarily.
Questions an auditor may ask
- Which assets may leave premises?
- How are high-risk travel scenarios handled?
- Show third-party custody evidence.
- What happens after loss?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.